CVE-2014-8750
Summary
| CVE | CVE-2014-8750 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-10-15 14:55:09 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Race condition in the VMware driver in OpenStack Compute (Nova) before 2014.1.4 and 2014.2 before 2014.2rc1 allows remote authenticated users to access unintended consoles by spawning an instance that triggers the same VNC port to be allocated to two different instances. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory SA60227 - OpenStack Nova VMware VNC Port Allocation Security Bypass Security Issue - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Third Party Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Third Party Advisory |
| oss-security - [OSSA 2014-035] Nova VMware driver may connect VNC to another tenant's console (CVE-2014-8750) | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List, Third Party Advisory |
| OpenStack Open Source Cloud Computing Software » Message: [openstack-announce] [OSSA 2014-035] Nova VMware driver may connect VNC to another tenant's console (CVE-2014-8750) | af854a3a-2127-422b-91ae-364da2661108 | lists.openstack.org | Vendor Advisory |
| Bug #1357372 “[oss-security] [OSSA 2014-035] Nova VMware driver ...” : Bugs : OpenStack Compute (nova) | af854a3a-2127-422b-91ae-364da2661108 | bugs.launchpad.net | Third Party Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Third Party Advisory |
| OpenStack Nova VMware driver 'get_vnc_port()' Function Race Condition Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.